Red: no clamav service exists yet, so verify-clamav finds no container. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
22 lines
1.0 KiB
Bash
22 lines
1.0 KiB
Bash
#!/usr/bin/env bash
|
|
#
|
|
# S-28 (#191): assert clamd scans over INSTREAM (EICAR → FOUND, clean → OK), against an
|
|
# ALREADY-RUNNING stack. Runs the check in a python:3-slim container on the stack network (the
|
|
# runner can't reach published ports — gitea-actions-gotchas.md §5/§6).
|
|
set -euo pipefail
|
|
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
|
|
av="$(docker ps -q --filter 'name=[-_]clamav[-_][0-9]+$' | head -1)"
|
|
[ -n "$av" ] || { echo "ERROR: no running clamav container — bring the stack up first" >&2; exit 1; }
|
|
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$av" | head -1)"
|
|
ip="$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$av")"
|
|
echo ">> network=$net clamav=$ip"
|
|
|
|
cid="$(docker create --network "$net" -e "CLAMAV=$ip" -e "CLAMAV_TIMEOUT=${CLAMAV_TIMEOUT:-60}" \
|
|
python:3-slim python /clamav-check.py)"
|
|
docker cp "$here/clamav-check.py" "$cid:/clamav-check.py" >/dev/null
|
|
rc=0; docker start -a "$cid" || rc=$?
|
|
docker rm -f "$cid" >/dev/null
|
|
exit $rc
|